Vulnerability Description
The Voo branded NETGEAR CG3700b custom firmware V2.02.03 allows CSRF against all /goform/ URIs. An attacker can modify all settings including WEP/WPA/WPA2 keys, restore the router to factory settings, or even upload an entire malicious configuration file.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netgear | Cg3700B Firmware | 2.02.03 |
| Netgear | Cg3700B | - |
Related Weaknesses (CWE)
References
- https://www.doyler.net/security-not-included/voo-netgear-cg3700b-vulnerabilitiesExploitThird Party Advisory
- https://www.doyler.net/security-not-included/voo-netgear-cg3700b-vulnerabilitiesExploitThird Party Advisory
FAQ
What is CVE-2019-13395?
CVE-2019-13395 is a vulnerability with a CVSS score of 8.8 (HIGH). The Voo branded NETGEAR CG3700b custom firmware V2.02.03 allows CSRF against all /goform/ URIs. An attacker can modify all settings including WEP/WPA/WPA2 keys, restore the router to factory settings,...
How severe is CVE-2019-13395?
CVE-2019-13395 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-13395?
Check the references section above for vendor advisories and patch information. Affected products include: Netgear Cg3700B Firmware, Netgear Cg3700B.